Phishing Risks Dealers Should Watch For After the CDK Cyberattack
Key takeaways
- Dealers should expect an increase in phishing attempts over roughly the next 60 days following the CDK cyberattack, likely from groups unrelated to the original CDK ransomware attackers.
- Regular system monitoring alone is not enough; findings from monitoring must also be remediated to meaningfully reduce risk.
- Even large, established compliance organizations like Finley have fallen victim to phishing attacks, showing that no dealership is immune.
- ARMP builds its compliance and phishing tools in-house and only outsources pen testing, vulnerability scanning, and remediation because those require a SOC and NOC.
- ARMP positions itself as a smaller, hands-on partner that helps dealers implement compliance programs rather than just supplying templates and resources.
Summary
Ransomware attacks like the CDK incident, and phishing breaches like the one that hit Finley, share a common aftermath: a surge in follow-on phishing attempts that exploit the confusion and disruption dealers are already dealing with. The speaker warns that even though the CDK event is winding down, a different set of bad actors will likely target dealership staff with phishing scams tied to the incident for a period of roughly 60 days. Dealers cannot fully prevent these attacks, since hackers continually find new cracks in systems, but they can mitigate risk through disciplined, ongoing monitoring rather than a one-time fix.
For a dealership, the takeaway is that monitoring alone is not enough; findings from vulnerability scans and pen testing have to be remediated, and staff need to be actively warned about incoming phishing attempts. The speaker stresses working with a partner who implements a program directly rather than just handing over templates, noting that ARMP builds its phishing tool in-house and only outsources pen testing, vulnerability scanning, and remediation to a dedicated SOC/NOC provider. He argues that even large, well-resourced compliance organizations like Finley's have been breached, so the real differentiator is a hands-on partner who helps implement and sustain the program, not just supply resources.
Transcript
Phishing risk following the CDK incident
Hi, my name's Terry Dortch. I'm with Automotive Risk Management Partners. Obviously I'm here to talk to you a little bit about the CDK and Finley incident. I don't want to beat a dead horse because obviously we're coming to the end of it, everything should be starting to clear up, the fog's going away, the whole bit. One of the things I do want to address is this: you know, Finley was a phishing situation where there was a lot of phishing that went through the store, they got caught into it. I'm going to tell you right now, this CDK event is going to bring a lot of that into the fray as well. So any of you dealers out there, just make your people aware of one thing: they need to be aware of any phishing attempts that are going to be going on over the next probably 60 days, and it'll all be wrapped around this whole CDK event and everything. And it's not even the same group that did the ransomware attack on CDK, there'll be different people that are doing this.
Why the ransomware attack was hard to prevent
So the bottom line here is there's not a whole lot that CDK could have done to prevent this ransomware attack, right? Because the bottom line is that this is always evolving, and these hackers are notorious for being able to get through the smallest of cracks in your system. I want to talk to you about how to stop this, or how to help prevent it, because it's going to be difficult as hell to stop, I mean, we all know that. But what you as dealers can do is you can mitigate this as much as possible, and the way that you do that is by following through with a strict program that monitors your system on a regular basis. And not just monitoring, but you have to take it to that next level and remediate any of the findings that you have.
Finding a partner to implement a monitoring program
So what I really want to talk to you about today too is make sure that when you're doing this, find a company that's going to partner with you and is going to actually sit and work with you on how to implement this program. You know, you can have templates and programs that people can provide you with, all different types of resources, but if you're not using those resources it means nothing. We at ARMP not only provide you with the resources, but we help you implement them. So you're not having to pick up a phone and call someone in California, you're not having to pick up the phone and call someone, you know, over in Bangladesh because that's their call center.
ARMP's small-team, hands-on approach
The bottom line here is we're a small run, well, when I say small, we're small in the sense that our team is small. Our management team doesn't need to be 25 or 30 people. We structure ourselves a lot differently in the sense that we're going to come in and we're going to take care of the dealer. We're there to make sure, can I promise you that you're not going to ever have a problem? No. What I am going to promise you, though, is that if you do have a problem, I'm going to be there for you, and I'm going to do everything that I can to help prevent any type of real loss. And I know that's a bold statement, but that's really what we do. Our whole program, and the way we're designed, and the way we function, is to come in and work with you people and help you mitigate any types of attacks like this.
In-house tools versus outsourced pen testing
Now, Finley had one of the largest organizations in the country that handles compliance for car dealers. They still had a phishing attack. I'll tell you right now, our phishing pro product is ours, we built it, not a third party. As a matter of fact, everything we do is in-house. The only thing that we outsource is our pen testing and vulnerability scanning and remediation, and that's because we need a SOC and a NOC, and obviously we can't put all that together, we can't formulate that whole program, so we have to outsource that. But we outsource it to a company that that's all they do, and we've designed our program to function within their environment and to function within yours, so that there's cohesion in everything.
Offer to help dealers build a cost-effective program
I'm telling you right now, if you're concerned about any of this, please give us a call. We'll be able to sit down with you and help you put together a program, and it's cost effective. I'm going to tell you right now, we'll put together a better program and we'll save you money over what you're spending right now in the market. I guarantee it, and if not, I'll tell you what, we'll give it to you for free. I guarantee you we're going to save you money and do a better job. So give us a call, the information is here on the screen. Thanks, take care.
Questions this video answers
Why should dealers worry about phishing after the CDK cyberattack?
The CDK event is expected to bring a wave of phishing attempts over roughly the next 60 days, similar to what happened with the Finley incident, and it will likely be carried out by different groups than the original CDK ransomware attackers.
Could CDK have prevented the ransomware attack?
According to the speaker, there was not a whole lot CDK could have done to prevent the ransomware attack because hacking methods are always evolving and hackers are notorious for exploiting even the smallest cracks in a system.
How can dealers reduce their risk of falling victim to phishing or ransomware?
Dealers can mitigate risk by following a strict program that monitors their systems regularly, and by going beyond monitoring to actually remediate any findings that turn up during that monitoring.
What does ARMP do differently from other compliance providers?
ARMP builds its own products in-house, such as its phishing pro product, rather than relying on third parties, and only outsources pen testing, vulnerability scanning, and remediation because those require a SOC and NOC that ARMP does not build itself.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
Covered in this video
- CDK cyberattack
- phishing attacks
- ransomware
- vulnerability scanning and remediation
- penetration testing